How to Configure SAML Authentication for zaico

Item

Details

Prior Confirmation

  • Prior configuration in zaico is required.

  • You need to create an account in zaico using the same email address as TrustLogin.

  • For the latest setup instructions, please check the manual provided by zaico.

Name ID

Email address

 

Custom attribute Note: For instructions on how to configure a custom attribute, see here

SP-side Configuration

 

Configured by the administrator

Request configuration from the SP

Provisioning

 

API-based provisioning supported (account management possible in TrustLogin)

 

SAML JIT provisioning supported (account management possible in TrustLogin; user deletion not supported)

None (accounts are created in each system)

Access Method

SP-Initiated SSO

 

IdP-Initiated SSO

Verified Operation by Device

PC - Browser

PC - Desktop App

iOS - Standard Browser (Safari)

iOS - TrustLogin Mobile App In-App Browser

iOS - Native App

Android - Standard Browser (Chrome)

Android - TrustLogin Mobile App In-App Browser

Android - Native App

Note: For the iOS and Android native apps, you need to scan the dedicated QR code while the app is installed.

TrustLogin Admin Page Settings

  1. Log in to TrustLogin, open the "Admin Page > App" menu, and click the "Register App" button in the upper right of the screen.
    01.png

  2. Search on the "Register Company App" screen and select "zaico (SAML)".
    zaico05.png

  3. Download the metadata using the "Download Metadata" button under "Identity Provider Information".03.png

Now, switch to configuring zaico.
Do not click the "Register" button yet — open zaico in a separate window.

zaico Settings

  1. Log in to zaico and open "Settings > Feature Settings".
    zaico04.png

  2. For "SAML Authentication", select "Enable".
    zaico.png

  3. Configure the "SAML Authentication" settings as follows.
    Entity ID Note down using the copy button
    Assertion Consumer Service URL Note down using the copy button
    Federation Metadata XML Upload the metadata you noted down from TrustLogin

    zaico02.png

  4. After uploading the metadata, the SAML information will be reflected. Click the "Apply" button to submit the SAML settings for approval.
    zaico03.png


  5. In "Other Settings", you can configure the login session. After logging in via SSO, you will be automatically logged out of zaico once the number of seconds set here has elapsed. Configure as needed and click "Update".


  6. Once ZAICO Inc. has finished configuring the metadata, you will receive an email indicating whether the request was approved.

  7. Once the SAML settings are approved, the "SAML Authentication" settings screen will display a "Dedicated Login URL" and a "Mobile QR Code" for use with the mobile app. Copy the "Dedicated Login URL" and note it down.
    Note: The "Dedicated Login URL" and "Mobile QR Code" can also be found in the approval email from ZAICO Inc.
    zaico10.png

Return to the TrustLogin Admin Page again.

TrustLogin Admin Page Settings (Continued)

  1. Configure the "Service Provider Settings" as follows.
    Login URL The "Dedicated Login URL" you noted down from zaico
    Entity ID The "Entity ID" you noted down from zaico
    ACS URL for the Service The "Assertion Consumer Service URL" you noted down from zaico

    zaico06.png

  2. Click the "Register" button to save.

Return to zaico again.

zaico Settings (Continued)

  1. In zaico, open "User Management > User List / Add" and select the user(s) to switch to SAML authentication login.
    zaico07.png

  2. For "Authentication Method", click "Change to SAML Authentication".
    zaico08.png

TrustLogin User Settings

① When a user adds the app from My Page

  1. Click the "Add App" button on "My Page".
  2. On the "Register App" screen, select "zaico (SAML)" and click the "Next" button in the upper right of the screen.
  3. If you want to change the "Display Name", enter it and click the "Register" button.

② When an administrator adds members

  1. Search for and click the "zaico (SAML)" app in the "Admin Page > App" menu.
  2. Click "Add Member", select the user to add from the member list, and click the "Register" button to add them.


Login Method

Running "zaico (SAML)" from My Page or the browser extension will take you to the zaico SSO login screen.

Click the "Log in with SSO" button to log in.
zaico11.png

Native App Login Method

For the iOS and Android native apps, you need to scan the dedicated QR code while the zaico app is installed. Please note that scanning the QR code without the app installed will not allow you to log in.

On a device with the native app installed, scan the QR code from either the zaico SAML authentication screen, the user information screen, or the approval email from ZAICO Inc.

[SAML Authentication Screen]
zaico10.png

[User Information Screen]
zaico09.png

Scanning the QR code will display the SSO login screen shown below. Clicking "Log in with SSO" will allow you to log in via SAML authentication.
zaico12.png

 

How to Configure SAML Authentication for zaico

Item

Details

Prior Confirmation

  • Prior configuration in zaico is required.

  • You need to create an account in zaico using the same email address as TrustLogin.

  • For the latest setup instructions, please check the manual provided by zaico.

Name ID

Email address

 

Custom attribute Note: For instructions on how to configure a custom attribute, see here

SP-side Configuration

 

Configured by the administrator

Request configuration from the SP

Provisioning

 

API-based provisioning supported (account management possible in TrustLogin)

 

SAML JIT provisioning supported (account management possible in TrustLogin; user deletion not supported)

None (accounts are created in each system)

Access Method

SP-Initiated SSO

 

IdP-Initiated SSO

Verified Operation by Device

PC - Browser

PC - Desktop App

iOS - Standard Browser (Safari)

iOS - TrustLogin Mobile App In-App Browser

iOS - Native App

Android - Standard Browser (Chrome)

Android - TrustLogin Mobile App In-App Browser

Android - Native App

Note: For the iOS and Android native apps, you need to scan the dedicated QR code while the app is installed.

TrustLogin Admin Page Settings

  1. Log in to TrustLogin, open the "Admin Page > App" menu, and click the "Register App" button in the upper right of the screen.
    01.png

  2. Search on the "Register Company App" screen and select "zaico (SAML)".
    zaico05.png

  3. Download the metadata using the "Download Metadata" button under "Identity Provider Information".03.png

Now, switch to configuring zaico.
Do not click the "Register" button yet — open zaico in a separate window.

zaico Settings

  1. Log in to zaico and open "Settings > Feature Settings".
    zaico04.png

  2. For "SAML Authentication", select "Enable".
    zaico.png

  3. Configure the "SAML Authentication" settings as follows.
    Entity ID Note down using the copy button
    Assertion Consumer Service URL Note down using the copy button
    Federation Metadata XML Upload the metadata you noted down from TrustLogin

    zaico02.png

  4. After uploading the metadata, the SAML information will be reflected. Click the "Apply" button to submit the SAML settings for approval.
    zaico03.png


  5. In "Other Settings", you can configure the login session. After logging in via SSO, you will be automatically logged out of zaico once the number of seconds set here has elapsed. Configure as needed and click "Update".


  6. Once ZAICO Inc. has finished configuring the metadata, you will receive an email indicating whether the request was approved.

  7. Once the SAML settings are approved, the "SAML Authentication" settings screen will display a "Dedicated Login URL" and a "Mobile QR Code" for use with the mobile app. Copy the "Dedicated Login URL" and note it down.
    Note: The "Dedicated Login URL" and "Mobile QR Code" can also be found in the approval email from ZAICO Inc.
    zaico10.png

Return to the TrustLogin Admin Page again.

TrustLogin Admin Page Settings (Continued)

  1. Configure the "Service Provider Settings" as follows.
    Login URL The "Dedicated Login URL" you noted down from zaico
    Entity ID The "Entity ID" you noted down from zaico
    ACS URL for the Service The "Assertion Consumer Service URL" you noted down from zaico

    zaico06.png

  2. Click the "Register" button to save.

Return to zaico again.

zaico Settings (Continued)

  1. In zaico, open "User Management > User List / Add" and select the user(s) to switch to SAML authentication login.
    zaico07.png

  2. For "Authentication Method", click "Change to SAML Authentication".
    zaico08.png

TrustLogin User Settings

① When a user adds the app from My Page

  1. Click the "Add App" button on "My Page".
  2. On the "Register App" screen, select "zaico (SAML)" and click the "Next" button in the upper right of the screen.
  3. If you want to change the "Display Name", enter it and click the "Register" button.

② When an administrator adds members

  1. Search for and click the "zaico (SAML)" app in the "Admin Page > App" menu.
  2. Click "Add Member", select the user to add from the member list, and click the "Register" button to add them.


Login Method

Running "zaico (SAML)" from My Page or the browser extension will take you to the zaico SSO login screen.

Click the "Log in with SSO" button to log in.
zaico11.png

Native App Login Method

For the iOS and Android native apps, you need to scan the dedicated QR code while the zaico app is installed. Please note that scanning the QR code without the app installed will not allow you to log in.

On a device with the native app installed, scan the QR code from either the zaico SAML authentication screen, the user information screen, or the approval email from ZAICO Inc.

[SAML Authentication Screen]
zaico10.png

[User Information Screen]
zaico09.png

Scanning the QR code will display the SSO login screen shown below. Clicking "Log in with SSO" will allow you to log in via SAML authentication.
zaico12.png